Deployment Architecture

Splunk logs are truncated to 10,000 characters

Madhusri
Engager

Hi,

Splunk logs are truncated to 10,000 characters.

Please let me know TRUNCATE=20,000 need to change in Splunk installed location or forwarder installation location .

Regards,

Madhusri R

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Madhusri,

TRUNCATE is an option of props.conf (for more infos see at https://docs.splunk.com/Documentation/Splunk/8.2.2/Admin/Propsconf)

so you have to put it in your Indexers and (if present) Heavy Forwarders.

Ciao.

Giuseppe

0 Karma

Madhusri
Engager

Hi @gcusello 

 

Could you please provide the indexers location ?

 

Regards,

Madhu

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Madhusri,

you could put props.conf in $SPLUNK_HOME/system/local, but I don't like it.

I hint to create a custom dedicated Technical Add-On (TA), called e.g. TA_Indexers, containing your props.conf and eventual other conf files.

The TA will be located in $SPLUNK_HOME/apps

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...